CVE-2026-48842

high
Published 2026-05-25 ยท Modified 2026-05-26
CVSS v3
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.1

Description

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

Predictions

Exploit likelihood
88%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2026-48842 NameCVE-2026-48842 DescriptionRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)โ€ฆ

CVE-2026-48842

NameCVE-2026-48842
DescriptionRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4604-1, DSA-6301-1
Debian Bugs1137507

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)bullseye1.4.15+dfsg.1-1+deb11u4vulnerable
bullseye (security)1.4.15+dfsg.1-1+deb11u9fixed
bookworm1.6.5+dfsg-1+deb12u8vulnerable
bookworm (security)1.6.5+dfsg-1+deb12u9fixed
trixie1.6.15+dfsg-0+deb13u1vulnerable
trixie (security)1.6.16+dfsg-0+deb13u1fixed
sid1.6.16+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesourcebullseye1.4.15+dfsg.1-1+deb11u9DLA-4604-1
roundcubesourcebookworm1.6.5+dfsg-1+deb12u9DSA-6301-1
roundcubesourcetrixie1.6.16+dfsg-0+deb13u1DSA-6301-1
roundcubesource(unstable)1.6.16+dfsg-11137507

Notes

https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b

OS impact

OSVersionStatusFixed in
debian debianbullseyefixed1.4.15+dfsg.1-1+deb11u9
debian debiansidfixed1.6.16+dfsg-1
debian debianbookwormfixed1.6.5+dfsg-1+deb12u9
debian debiantrixiefixed1.6.16+dfsg-0+deb13u1
debian debianforkyfixed1.6.16+dfsg-1

References

CWEs

CWE-89

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.